Ransomware victim disclosure
← All victimsTokyo Civil
listed as tokyocivil.co.jp · Claimed by Safepay · listed 12 hours ago
Status timeline
- ListedJun 15, 2026
- Data leakeddate unknown
At a glance
- Group
- Safepay
- Status
- Data leaked
- Country
- Japan
- Sector
- Construction
- Listed on leak site
- Jun 15, 2026
About the victim
AI dossier — public-source company profileTokyo Civil is a civil engineering company established in 2020 that specializes in public infrastructure and construction projects serving the Tokyo metropolitan area.
- Industry
- Civil Engineering & Public Infrastructure
- Founded
- 2020
Attack summary
Severity: medium — Data has been published by the threat actor (confirmed disclosure status), indicating successful exfiltration. However, no specific data inventory, proof file count, or sensitive data categories are detailed in the truncated post. The company's focus on public infrastructure suggests potential operational sensitivity, but without more specifics, assessment is limited.The SafePay group claims to have compromised Tokyo Civil and published data from the attack. The specific data categories and attack methods (encryption, exfiltration, or both) are not detailed in the available post excerpt.
What the group claims
Established in 2020, the company specializes in public infrastructure and civil engineering projects, serving primarily the Tokyo metropolitan area and …
Sources
Source
Indexed 12 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

